VA-003 · domain
troubleshooting
Practise HashiCorp Vault Associate VA-003 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (366)
Click any question to see the full explanation, or start a practice session above.
A Vault operator deploys a single Vault server using Integrated Storage (Raft) as the storage backend. After initializing Vault, the operator notices that the server is marked as sealed and cannot serve requests. The operator has the unseal keys but wants to understand the architectural reason why Vault starts sealed after initialization. Which statement best explains why Vault is sealed immediately after initialization?
Medium2An application needs to read a secret using the Vault API after authenticating with an AppRole RoleID and SecretID. The application has already obtained a Vault token. Which API endpoint should be called to read a secret at 'secret/data/myapp' with the token?
Easy3A security engineer is onboarding a new application team to Vault. The team needs to understand how Vault manages the lifecycle of secrets issued by the database secrets engine. The engineer explains that Vault attaches a lease to dynamic secrets and that the lease defines the secret's validity period. Which statement accurately describes the relationship between a lease and a dynamic secret?
Easy4A Vault operator is examining the architecture of a Vault cluster and wants to understand how client requests are routed to the active node. Which component is responsible for forwarding requests from standby nodes to the active node?
Medium5A platform team manages a fleet of on-premises Linux servers that are not joined to any cloud provider or Active Directory domain. They want each server to authenticate to Vault automatically at boot without embedding a long-lived token in a configuration file. The team already maintains an internal PKI that issues X.509 certificates to every server. Which authentication method should they enable to meet these requirements with the least new infrastructure?
Medium6A small startup wants to run Vault in a development environment with minimal operational overhead. They need to store secrets in memory only, without any persistence. Which storage backend should they choose?
Easy7A development team wants to encrypt sensitive data before storing it in a database. They don't want to manage encryption keys themselves. Which secrets engine should they use?
Medium8A role in Vault's database secrets engine is configured with default_ttl=30m and max_ttl=2h. An application requests credentials and then successfully renews the lease twice, each time receiving the full default TTL. What is the longest total time the credential can remain valid from its original issue time?
Hard9A Vault operator accidentally revoked a token that was used to lease many database credentials. What happens to the leases associated with that token?
Medium10A platform team wants Kubernetes pods to authenticate to Vault by presenting their service account token, with Vault verifying the token's validity against the Kubernetes API and checking the pod's namespace and service account name. Which auth method should the team enable?
Hard11An e-commerce application integrates with Vault's transit secrets engine to encrypt sensitive customer data before storing it in a database. The operations team regularly rotates the encryption key (my-key) for compliance. Recently, after a rotation, some old ciphertexts could not be decrypted, causing data retrieval failures. The team checked the key configuration and found that the key version used for encryption (version 2) is still present, but decryption fails with an error: 'decryption key version is not available for decryption'. They verified that the ciphertext includes the key version. What is the most likely cause and resolution?
Hard12A Vault operator wants to manage lease durations for secrets issued by a PKI secrets engine. Which two actions can they take to affect the lease duration of certificates?
Medium13A Vault administrator is designing a disaster-recovery runbook for dynamic secrets and needs to document the ways leases can be terminated or cleaned up. Which two statements correctly describe lease revocation behavior in Vault? (Choose two.)
Hard14A Vault operator runs 'vault token lookup s.abc123' and sees that the token type is 'service', renewable is true, but the ttl is 30m and creation_ttl is 1h. The token has num_uses set to 0. What is the most likely explanation for the discrepancy between ttl and creation_ttl?
Hard15A Vault administrator needs to create a policy that grants users read access only to the secrets that belong to their own team. The team membership is stored in an external identity provider and mapped to Vault entity aliases. The administrator wants to use a templated policy that references the entity's metadata. Which policy syntax accomplishes this goal?
Hard16An administrator receives an access denied error when trying to use the token accessor to revoke a token. The administrator's token has the following policy capabilities: path "auth/token/revoke-accessor" { capabilities = ["create", "update"] }. What is the issue?
Hard17A security team wants to allow applications to authenticate to Vault without storing any secrets in configuration files. The applications run on AWS EC2 instances with an IAM role attached. Which Vault authentication method leverages the EC2 instance metadata to obtain credentials?
Easy18Which TWO authentication methods are designed for human users? (Choose two.)
Easy19A team is migrating from a monolithic application to microservices. Each microservice needs to authenticate to Vault using its own AppRole. The security team wants to enforce that each AppRole can only read secrets from its own dedicated path (e.g., service-a can only read from 'services/service-a/*', service-b from 'services/service-b/*'). They have created the AppRoles and policies. However, during testing, they notice that service-a can read secrets from service-b's path. The administrator checks the policy for service-a and sees it has a 'capabilities' list on 'services/service-a/*' and also 'services/service-b/*' by mistake. They correct the policy, but the issue persists. What is the most likely reason that service-a still has access?
Medium20A DevOps team wants to automate authentication to Vault for Jenkins jobs running on AWS EC2 instances. Which authentication method is most appropriate and secure for this use case without storing long-lived credentials?
Easy21A token with a policy that explicitly denies 'read' on 'secret/engineering/private' is issued. The same token also has another policy that grants 'read' on 'secret/engineering/*'. What is the result when the token tries to read 'secret/engineering/private'?
Hard22Refer to the exhibit. What operation was performed on the secret "mysecret"?
Easy23A Vault administrator is troubleshooting a Vault cluster using integrated storage (Raft). The cluster has three nodes: node1 (active), node2 (standby), and node3 (standby). The administrator runs `vault operator raft list-peers` and sees that node3 is listed as a non-voter. What is the most likely reason for node3 being a non-voter?
Medium24A Vault administrator is configuring a new Vault cluster with Integrated Storage (Raft). The administrator wants to ensure that the cluster can tolerate the failure of one node without data loss and that writes remain available. What is the minimum number of nodes required, and what is the recommended configuration for high availability?
Hard25A new engineer authenticates to Vault and receives a token. The engineer's manager asks which policies are attached to that token and when it will expire, so the team can plan a permissions review. Which command should the engineer run to display this information about their own token?
Easy26A security team needs to grant a service account the ability to read secrets from the path 'secret/data/backup' and also to update the secret at that same path. Which policy correctly implements this requirement?
Easy27A platform team stores KV v2 secrets under the mount 'kv-prod'. They need a policy that lets an application read only the metadata (not the underlying secret values) for every path under 'kv-prod/apps/', including the ability to enumerate keys. Which policy stanza satisfies this requirement?
Medium28An application stores ciphertext produced by a Vault transit key named `orders` in a database. The security team rotates the key with `vault write -f transit/keys/orders/rotate`. After rotation, the application reports that decryption of previously stored records fails. The key was never deleted or reconfigured. What is the most likely cause?
Medium29A user wants to view information about their current token, including its policies and TTL. Which TWO CLI commands can be used?
Medium30A security team needs to create a Vault policy that allows a token to read secrets under 'secret/data/finance/*' but explicitly denies access to 'secret/data/finance/salaries'. The policy must also allow listing all secrets under 'secret/data/finance/'. Which policy definition correctly achieves this?
Hard31Which THREE steps are required to configure the database secrets engine for a MySQL database?
Medium32A platform team runs a Vault cluster where many applications obtain dynamic AWS credentials from the aws secrets engine. During an incident, an operator needs to stop all credential usage tied to a compromised IAM role without disrupting other roles. The operator has a root token and wants to revoke every lease associated with that specific role. Which approach accomplishes this?
Medium33A CI/CD pipeline needs to generate thousands of short-lived tokens each day for jobs that run for at most 5 minutes. The tokens should not be renewable or revocable individually. Which token type should be used?
Medium34Which THREE of the following are true about the KV v2 secrets engine? (Select exactly 3.)
Hard35A large enterprise runs Vault in a high-availability cluster with integrated storage (Raft). They notice that read requests are not being evenly distributed across nodes, causing some nodes to have high load. They want to offload read operations to standby nodes. What feature should they enable to achieve this?
Hard36An administrator notices that after revoking a specific lease, the underlying database credential is still accessible. What is the most likely cause?
Hard37A security team must immediately invalidate every dynamic database credential issued under a specific role named app-readonly, across all database mounts, without knowing individual lease IDs. Which Vault command accomplishes this?
Medium38An administrator configures a database secrets engine with a role that uses 'creation_statements' and 'revocation_statements'. However, when a lease expires, the database user is not revoked. What is the most likely cause?
Hard39Which TWO of the following are true about token accessors?
Medium40Which three statements about lease renewal are correct? (Choose three.)
Hard41An application team is using a batch token to authenticate to Vault for a long-running data processing job. The token was created with a TTL of 8 hours and no explicit max TTL. After 4 hours, the application attempts to renew the token but receives an error. What is the most likely reason for the renewal failure?
Medium42An application needs to encrypt sensitive data before storing it in a database. The security team wants to use Vault's encryption as a service to avoid managing encryption keys. Which Vault secrets engine should they enable?
Easy43A DevOps team uses Vault to store database credentials via the database secrets engine. They notice that after the default lease duration, applications receive errors when trying to connect. The team wants to ensure that applications automatically renew leases before expiration. What should they do?
Medium44An application authenticates to Vault using the AppRole auth method and needs to retrieve the token's remaining TTL and renewable status programmatically. The application already has a valid token and calls the lookup-self endpoint. Which response fields should it read to determine whether the token can be renewed and how long it remains valid?
Medium45Refer to the exhibit. A user with this policy attempts to read 'secret/data/team/admin'. What will happen?
Medium46A platform team is standardizing on the transit secrets engine for application-level encryption and wants to understand what the engine can and cannot do before rollout. Which TWO statements accurately describe transit engine behavior? (Choose two.)
Medium47Which TWO statements are true when troubleshooting a failed Vault CLI command?
Easy48A Vault policy must allow a service to read secrets from "secret/data/app" and also be able to renew its own token. Which two policy statements are necessary and sufficient for this requirement? (Select two.)
Hard49A Vault cluster uses Integrated Storage. During a planned upgrade, the administrator wants to minimize downtime. Which upgrade strategy should be used?
Hard50Which two commands can be used to manually revoke leases? (Choose two.)
Medium51What is the purpose of the Seal/Unseal process in Vault architecture?
Easy52After a Vault migration, some leases are no longer valid and cause errors. What is the best way to force a cleanup of all leases under a specific mount without affecting other mounts?
Hard53An organization has two Vault clusters in different geographic regions and wants to replicate secrets from the primary cluster to the secondary cluster for disaster recovery. Which Vault replication feature should they use?
Easy54A DevOps team needs to provide temporary database credentials to applications without storing long-lived passwords. Which secrets engine should they use?
Easy55What happens when a lease reaches its TTL?
Easy56Match each Vault audit device to its output destination.
Medium57A security engineer needs to choose an authentication method for a set of microservices running in a Kubernetes cluster that require short-lived secrets. The method should leverage the pod's identity. Which method is best?
Easy58Refer to the exhibit. Which authentication method is currently enabled for production applications?
Easy59An organization uses Vault to issue certificates via the PKI secrets engine. They have set the default lease TTL on the PKI mount to 72h, and the role's ttl to 24h. A user requests a certificate with a requested TTL of 48h. What will be the actual TTL of the issued certificate?
Hard60A token has the properties shown in the exhibit. A user attempts to use this token to write a secret to 'secret/data/myapp'. The token fails with a permission denied error. What is the most likely cause?
Medium61A security team wants to store static secrets like API keys in Vault. They need the secrets to be versioned and support rollback. Which secrets engine should they use?
Easy62A Vault operator needs to let an on-premises LDAP directory's groups map directly to Vault policies, but the directory does not implement any OIDC or SAML endpoints. Which auth method should the operator enable to authenticate users against that directory?
Medium63An operator inspects a Vault policy and finds a rule granting read on database/creds/reporting. Applications using tokens bound to this policy can fetch credentials but receive permission denied when they attempt to extend them. Which capability must be added to the policy to allow lease renewal?
Medium64A Vault cluster with three nodes using Integrated Storage (Raft) is healthy with one active and two standby nodes. A network partition isolates the active node. What will happen?
Medium65A company uses Vault for secrets management. They want to authenticate using GitHub tokens, but only for users who are members of a specific GitHub team. What must be configured?
Hard66The CLI command returns a 403 error. What is the most likely cause?
Easy67A startup uses Vault to manage secrets for their web application. They currently have a single admin user who authenticates with a root token. They want to allow two developers to authenticate with their own credentials and restrict them to read-only access to a specific path 'secret/data/webapp'. They decide to use the Userpass auth method. The admin creates a user 'dev1' with password 'password123' and assigns a policy 'webapp-readonly' that grants read capability on 'secret/data/webapp'. However, when dev1 tries to log in, Vault returns a permission denied error. The admin checks the token and sees no policies attached. What is the most likely issue?
Medium68A user's token was revoked by an administrator, but the user can still read secrets from a KV v1 secrets engine. What is the most likely reason?
Medium69A company is migrating from a file storage backend to Consul. Which Vault command should be used to move the data?
Easy70Which TWO best practices should be followed when tuning secrets engine mounts?
Hard71A company runs its containerized workloads on multiple Kubernetes clusters and also maintains a number of legacy virtual machines running critical applications. The Vault cluster is deployed outside Kubernetes and is used to manage secrets for both environments. The DevOps team has configured the Kubernetes auth method for pods in the Kubernetes clusters, but they are experiencing authentication failures for pods in one specific namespace. Meanwhile, legacy VMs cannot authenticate at all because they are not part of any Kubernetes cluster. The Vault administrator needs to enable authentication for all workloads while minimizing changes to existing applications. The administrator has received the following requirements: containerized pods should authenticate without manual token distribution, legacy VMs should use a method that supports machine-oriented authentication with short-lived tokens, and all authentication should be auditable. Which course of action should the administrator take?
Medium72A company's CI system runs outside any cloud provider and must authenticate to Vault without embedding a long-lived secret in its build scripts. The security team wants the CI job to prove its identity using a credential that Vault validates against the CI platform itself. Which auth method best fits this requirement?
Medium73A user wants to log in using the userpass auth method with username 'jdoe' and password 'p@ssw0rd'. What is the correct API endpoint and request?
Easy74Refer to the exhibit. A Vault policy allows 'list' on 'secret/data/*'. A user tries to list keys under 'secret/data/' and gets a permission denied error. What is the most likely reason?
Easy75A user attempts to read a secret at path 'secret/data/app' and receives a 403 Forbidden error. What is the most likely cause?
Medium76Which TWO of the following are benefits of using Vault's transit engine for encryption as a service?
Hard77A company with strict security requirements uses Vault's Transit secrets engine to encrypt data in a microservices architecture. They have multiple applications that each require a unique encryption key. The security team wants to enforce key rotation every 30 days for all keys, and also require that keys be destroyed after they are no longer used. The application team is concerned that key rotation might cause downtime because applications need to re-encrypt data. The Vault architect needs to design a key management solution. What is the best approach?
Hard78A security architect is designing authentication for an internal tool that must verify a user's hardware-backed token on a smart card before granting access to secrets. The tool already has a PKI issuing client certificates to each user, and the architect wants Vault to validate the client certificate chain during login. Which auth method should be used, and what is the key configuration requirement?
Hard79A security team encrypts records with a transit key and stores the resulting ciphertext. Months later they rotate the key several times. An application now needs to read old records, and the team also wants future writes to use only the newest key version without breaking decryption of the legacy rows. What is the accurate behavior of the transit engine in this situation?
Hard80A developer wants to encrypt data using Vault's transit engine with a key named 'payment-key'. The key already exists and is set to allow encryption. Which API path should the developer use to encrypt the data?
Easy81A security team must delegate policy management to a group of operators without giving them the ability to grant themselves capabilities on protected paths such as 'sys/*' or 'auth/token/*'. Which combination of policy rules best implements this delegation safely?
Hard82A platform team runs a nightly batch job that authenticates to Vault with the AppRole auth method and receives a token with a 30-minute TTL. The job occasionally overruns and hits 'permission denied' errors mid-run. The team wants the token to stay valid as long as the job keeps working, without the job re-authenticating. Which token attribute should the AppRole role be configured with when the token is issued?
Medium83A security engineer is reviewing Vault's architecture and asks about the component that stores the actual encrypted data. Which Vault component is responsible for persisting encrypted secrets and configuration data?
Easy84A developer wants to encrypt a string "hello" using Vault's transit engine. What must they send in the API request?
Easy85An operator needs to enable the KV v2 secrets engine at the path 'team-alpha'. Which command should they run?
Easy86A Vault cluster uses DR replication. The primary cluster fails, and the DR secondary is promoted to primary. After promotion, some secret data written to the primary shortly before the failure is missing on the new primary. What is the most likely reason?
Hard87A consulting firm deploys Vault to multiple tenants. Each tenant uses the OIDC auth method with its own identity provider, but the security team observes that users from one tenant occasionally receive policies intended for another tenant. The OIDC mounts were configured separately, and each uses a distinct default_role. Which configuration issue most likely explains the cross-tenant policy assignment?
Hard88A company needs to generate short-lived, dynamic database credentials for its MySQL instances. Which secrets engine should be configured?
Easy89A Vault administrator has enabled the PKI secrets engine and configured a root CA. They now need to issue certificates for multiple internal services, each with its own common name (CN). Which is the most efficient way to issue certificates while maintaining security?
Medium90Refer to the exhibit. A token has this policy. Which action can the token perform?
Easy91An operator needs to perform token lifecycle operations. Which THREE API endpoints are valid for token-related actions?
Hard92An application stores user profile documents in a database and must encrypt field values with Vault's transit engine. A reviewer notes that anyone with the application's token could still send arbitrary ciphertext to the decrypt endpoint and read the result. The team wants to limit blast radius if the token leaks. Which transit engine capability best reduces this risk?
Medium93During a security assessment, a penetration tester discovers that Vault's seal configuration uses a single master key stored in a file on the server. The attacker gains root access to the server and retrieves the unseal key. What is the best mitigation to prevent this scenario?
Hard94After migrating from an older version of Vault, the operator wants to replace the deprecated 'generic' secrets engine with a modern alternative. Which secrets engine should be used to store static key-value pairs?
Easy95A company uses Vault Enterprise with Performance Replication. The primary cluster is in us-east-1, and a secondary cluster is in eu-west-1. Clients in eu-west-1 report that they receive stale data when reading from the local secondary cluster's active node. What is the most likely cause?
Hard96A DevOps engineer configures the AWS secrets engine to assume a specific IAM role for generating dynamic credentials. The engine is enabled and the root configuration is set. Which parameter is essential in the role configuration to allow assuming the IAM role?
Hard97A DevOps team needs to encrypt sensitive configuration data before storing it in a version control system. They want to use Vault's encryption as a service to encrypt the data using a named encryption key. Which Vault path should they use to perform the encryption?
Easy98Refer to the exhibit. A user deletes the current version of 'secret/myapp' using 'vault kv delete secret/myapp'. What happens to the version?
Medium99An organization previously used userpass auth and is migrating to LDAP auth. After enabling LDAP and configuring the bind user, users can authenticate but their policies do not apply. What is the most likely cause?
Medium100Which TWO of the following are components of Vault's architecture? (Choose two.)
Medium101Which Vault CLI command is used to authenticate a user with a username and password to the userpass auth method?
Easy102A company is deploying Vault in a high-availability configuration across three data centers. They need to ensure that if the active Vault node fails, another node can take over without manual intervention. Which Vault feature should they configure?
Medium103A platform team uses Vault to issue short-lived tokens to external contractors. The security policy requires that every contractor token must be traceable back to the contractor's identity, and that a token can never be renewed beyond its initial TTL. The team creates tokens with the default settings. A contractor later reports that their token stopped working after its TTL expired, but they were able to renew it several times before that. Which token parameter should the team have configured to enforce the policy?
Medium104An administrator enables the database secrets engine for PostgreSQL. After configuring the connection, running `vault write database/config/someconfig` yields error: 'x509: certificate signed by unknown authority'. What is the most likely cause?
Hard105A database secrets engine is configured at database/ with a connection to PostgreSQL and a role named app-readonly. The role uses creation_statements to create a user with a random password and a TTL of one hour. An application retrieves credentials and uses them successfully, but after the lease expires the database user still exists and can log in. Which configuration change should the administrator make to ensure the user is removed when the lease ends?
Hard106A Vault administrator needs to delegate the ability to create tokens to a user without granting full administrative privileges. Which token type should the administrator create for the user to allow them to create tokens with specific policies?
Easy107Which TWO of the following Vault CLI commands can be used to write data to Vault?
Medium108An administrator wants to retrieve the value of a secret stored at the path 'kv/secret/mykey' using the Vault CLI. Which command should they use?
Easy109Which token type should be used for short-lived credentials that do not need to be renewed?
Medium110A platform engineer has issued dynamic AWS credentials through Vault's AWS secrets engine and wants to extend the usable lifetime of that credential before it expires. Which Vault CLI command allows the engineer to request additional time on the lease?
Easy111A security engineer is troubleshooting why a Vault token cannot be renewed. The token was created with a TTL of 4 hours and is renewable. After 2 hours, the engineer attempts to renew it using `vault token renew <token>` but receives the error: "lease not found". The engineer confirms the token is still valid and not expired. Which of the following is the most likely cause?
Hard112What is the purpose of a token's "period" attribute?
Easy113A development team is building a microservices application that needs to encrypt sensitive customer data before storing it in a shared database. They want to minimize changes to their existing code and avoid managing encryption keys themselves. Which Vault feature should they use?
Medium114Where can you view a list of all active tokens in Vault?
Easy115A company stores static secrets in Vault and requires that all data is encrypted at rest in the storage backend. Which Vault feature provides this encryption?
Easy116An application is failing to decrypt data using the transit secrets engine. The ciphertext was generated with key 'my-key' version 3, but the engine currently shows key version 5. What is the most likely cause of the failure?
Hard117An administrator wants to use Vault's authentication method that allows users to log in with their corporate credentials via a federated identity system. The credentials are stored in an external identity provider (IdP) and Vault should not store any passwords. Which authentication method should be configured?
Medium118An organization uses the AWS secrets engine to generate IAM users dynamically. They notice that the generated IAM user is not immediately available for use in AWS. What is the most likely reason?
Hard119A Vault operator needs to enable the `userpass` auth method at the path `auth/legacy-userpass` and then create a user named `svc-backup` with a password, all from a CI script. Which single command correctly enables the auth method at that custom path?
Medium120A DevOps engineer needs to create a token that can only read secrets under the path 'secret/engineering'. What is the recommended approach?
Easy121A developer wants to authenticate to Vault using a username and password without any external identity provider. Which authentication method should be enabled?
Easy122A company needs to automatically generate short-lived database credentials for developers. Which secrets engine should they use?
Easy123A company has a Vault cluster and wants to allow applications running in Kubernetes pods to authenticate without storing static secrets. Which Vault authentication method is specifically designed for Kubernetes?
Medium124A token is created with policies 'default' and 'web-app'. Later, a parent token's policy is updated to add 'logging'. The child token's policies are not updated. What will happen when the child token is used?
Hard125An organization is implementing Vault policies for the first time. They want to ensure that policies are easy to manage and follow the principle of least privilege. Which approach should they take when creating policies?
Easy126A Vault administrator needs to allow users to authenticate using their existing corporate Active Directory credentials. The administrator has configured the LDAP authentication method but users cannot log in. The Vault logs show 'LDAP bind successful' but then 'user not found in group' error. What is the most likely issue?
Medium127A company has deployed Vault with an LDAP auth method and has created entity aliases for all users. The company uses KV v2 secrets engine mounted at 'secret/'. Each team's secrets are stored under a path like 'secret/data/team_<team_name>/'. They have multiple teams (engineering, marketing, sales). Currently, an administrator manually creates a separate policy for each team, e.g., path "secret/data/team_engineering/*" { capabilities = ["read", "list"] }. This is becoming cumbersome as new teams are added. The administrator wants to create a single policy that dynamically grants read access to the secrets path corresponding to the user's team, which is stored in the entity's metadata as 'team'. The LDAP auth method is configured to sync group memberships and map to entity aliases, and the entity metadata is correctly populated. Which approach should the administrator take?
Medium128A platform team is designing an encryption-as-a-service layer with the transit secrets engine for several internal applications. They want to minimize the amount of sensitive data that reaches application memory and reduce the operational cost of rotating keys. Which TWO design choices align with how the transit engine is intended to be used? (Choose two.)
Hard129A company uses both userpass and AppRole authentication methods. They notice that tokens issued via AppRole are not properly revoked when the corresponding secret_id is deleted. Which concept explains this behavior?
Hard130A Vault cluster configured with auto-unseal using AWS KMS is deployed across two availability zones. After a network partition, the standby node remains sealed while the active node is unsealed and serving requests. What is the most likely reason the standby cannot unseal?
Hard131A DevOps team is using Vault's database secrets engine to generate dynamic credentials for a PostgreSQL database. They notice that the lease duration is set to 24 hours, but security policy requires that credentials expire after 1 hour. What should the team do to enforce the 1-hour expiration without changing the default lease TTL for all secrets?
Medium132An admin creates a token with TTL=48h and explicit_max_ttl=120h. The token is renewed every 24h. After 10 days, will the token still be valid?
Hard133Refer to the exhibit. Based on the output from 'vault status', which statement is true?
Hard134A developer wants to inspect the metadata of the current Vault token, including its attached policies, TTL, and whether it is renewable, using a single CLI command. Which command should the developer run?
Easy135A Vault administrator is writing a policy for a monitoring tool that must be able to list all secrets under the 'secret/metadata/finance/' path and read the metadata of individual secrets, but must not read the secret data itself. Which policy snippet correctly grants only these permissions?
Medium136An application uses a Vault token with a policy that grants read access to secrets. The security team wants to ensure that if the application is compromised, the token cannot be used after a certain time even if the attacker has the token. What is the best approach?
Hard137A compliance team is evaluating the Vault transit secrets engine as encryption as a service for several internal applications. They want to confirm which statements accurately describe how the engine behaves. (Choose two.)
Medium138A security architect is designing a secrets management solution with Vault. Which THREE secrets engines are most appropriate for dynamically generating credentials for external systems?
Hard139Drag and drop the steps to create and use a periodic service token in Vault into the correct order.
Medium140An organization wants to use Vault to generate AWS IAM users with specific managed policies attached. They have configured the AWS secrets engine with the appropriate IAM credentials. What step is required to ensure each generated user gets the correct policies?
Medium141Refer to the exhibit. A Vault administrator starts a Vault server and receives this error. What is the most likely cause?
Easy142A platform team runs Vault in an on-premises data center. Their legacy monitoring appliance cannot present a TLS client certificate and has no cloud identity provider, but it does have a dedicated filesystem path where it can read a small configuration file written at deployment time. The team wants the appliance to authenticate on a schedule with credentials that can be issued per appliance, scoped by policy, and revoked without affecting other appliances. Which authentication method best fits this requirement?
Medium143A cloud engineer is scripting against the Vault HTTP API and must authenticate, then read a KV v2 secret, using only `curl`. Which TWO request elements are required for the read to succeed? (Choose two.)
Hard144An administrator needs to revoke a token but wants to keep all child tokens that were created using this token as the parent. Which revocation operation should be used?
Easy145Refer to the exhibit. A user with this policy attempts to read the secret at path "secret/data/team-a/admin". What will happen?
Medium146A DevOps team wants to authenticate a CI/CD pipeline running on a Jenkins server outside Kubernetes. The pipeline needs to obtain short-lived tokens to read secrets. Which authentication method should be used?
Easy147An admin is troubleshooting a Vault cluster where some dynamic secrets leases are not being revoked after their TTL expires. The admin confirms that the TTLs are set correctly. Which Vault component is responsible for revoking expired leases?
Medium148Which Vault component is responsible for encrypting data before storing it in the storage backend?
Easy149Which TWO are benefits of using Vault's encryption as a service?
Easy150A Vault admin needs to revoke all leases under the `database/creds/readonly` path without revoking leases from other paths. Which command should the admin use?
Easy151A DevOps team is using Vault tokens for authentication in CI/CD pipelines. They notice that tokens are often expired before the pipeline completes, causing failures. Which Vault feature should they use to address this without manual intervention?
Medium152A security team is configuring the AWS secrets engine to issue dynamic IAM credentials. They want to allow Vault to assume an IAM role and generate temporary credentials for consumers. Which TWO configuration elements are required to enable this workflow? (Choose two.)
Medium153A Vault administrator is creating a policy for an application that needs to read a PKI role configuration and also generate certificates using that role. The PKI secrets engine is mounted at 'pki/'. Which policy snippet grants the minimum required capabilities?
Hard154A company runs multiple microservices in a Kubernetes cluster. Each microservice authenticates to Vault using a service token created via the token auth method. The tokens are created with a default TTL of 72h, a max TTL of 168h, and renewable set to true. The services are configured to renew their tokens when the remaining TTL drops below 24h. Recently, some tokens have been expiring prematurely, causing service outages. Upon investigation, you find that the expired tokens were created with a role that includes explicit_max_ttl = 72h. The services see the TTL decreasing normally, but then it jumps to zero even though the services attempted renewal. What is the most likely cause and correct action?
Easy155A Vault administrator is investigating a production incident where an application's dynamic database credentials stopped working earlier than expected, even though the lease had not reached its maximum TTL. The administrator reviews the role configuration and finds default_ttl=1h and max_ttl=24h. The application typically renews its lease every 30 minutes. Which factor most likely explains why the credentials became invalid before max_ttl was reached?
Hard156A Vault administrator is building a policy for an application team that needs to manage PKI certificates issued by the 'pki_int' intermediate mount. The team must be able to generate new certificates from the 'web-server' role and revoke certificates, but must not be able to modify the role, generate a root CA, or configure the mount. (Choose two.)
Medium157Refer to the exhibit. A DevOps engineer runs `vault read -format=json transit/keys/mykey` and receives the output shown. A microservice attempts to decrypt data that was encrypted with version 1 of the key. Will the decryption succeed?
Medium158A developer wants to authenticate to Vault using LDAP credentials. Which CLI command should they use?
Easy159An organization uses Vault with LDAP authentication. Users report they are unable to log in, and the administrator sees errors like 'LDAP bind failed: invalid credentials' in the Vault logs. The LDAP server is reachable. What is the most likely cause?
Hard160Drag and drop the steps to set up Vault's Transit secrets engine for encryption/decryption into the correct order.
Medium161A Vault operator runs `vault status` and sees the output above. The Vault cluster is in production and currently unresponsive to API requests. What is the most likely cause of the unresponsiveness?
Easy162A developer is writing a microservice that must encrypt a small JSON payload using the transit secrets engine's 'orders' key, but the service must never be able to read the key material itself. Which API call should the service use to obtain ciphertext?
Easy163A platform team operates Vault in a hybrid cloud. They want a single authentication method that lets employees use their existing cloud provider identity (e.g., AWS IAM role, Azure managed identity) to log in without distributing Vault-specific credentials. Which authentication method should they enable?
Medium164A DevOps team needs to encrypt large files (several GB) using Vault's transit engine. What is the recommended approach?
Easy165Refer to the exhibit. A developer reports that a token they created using `vault token create -policy=my-policy -ttl=2h` is no longer working after 1 hour. The token lookup output shows the token details. What is the most likely cause?
Hard166What is the primary purpose of the Vault transit secrets engine?
Easy167An application team needs to encrypt short-lived session tokens before writing them to a Redis cache. They want to avoid handling or storing encryption keys in the application and need the ability to decrypt tokens later without re-encrypting. Which Vault transit secrets engine operation should they use to protect the data at write time?
Easy168A new Vault administrator unseals Vault using a single unseal key, but the Vault remains sealed. What is the most likely cause?
Easy169An administrator has created a policy file named 'app-policy.hcl'. Which command should they use to upload this policy to Vault?
Easy170Which TWO of the following are valid uses of a token accessor? (Select exactly 2 options.)
Easy171A platform team runs Vault in a hybrid cloud and wants to let engineers log in with their existing corporate identities held in Okta, without creating separate Vault usernames or passwords. The Okta tenant supports OpenID Connect and exposes a discovery document. Which authentication method should they enable to meet this requirement with the least administrative overhead?
Medium172A junior administrator writes a policy file and applies it with 'vault policy write app-read app-read.hcl'. Later, a token created against this policy can read secrets it was never meant to see. The administrator wants to confirm exactly what the policy grants before rotating credentials. Which command displays the parsed, effective rules of the stored policy?
Easy173Which TWO statements about Vault's Storage Backend are correct?
Easy174Drag and drop the steps to configure Vault's PKI secrets engine to issue certificates into the correct order.
Medium175An application encrypts records with the transit engine and stores the ciphertext. A compliance requirement mandates rotating the encryption key every 90 days, but the existing records must remain readable and the application cannot be changed to re-encrypt them all at once. What should the operator do?
Hard176An operator wants to enable the database secrets engine at a custom path 'db-creds'. Which command should be used?
Medium177Refer to the exhibit. A user has a token with a policy that grants 'read' on 'secret/*'. The user attempts to read the secret at 'secret/data/app' using `vault kv get secret/data/app` but receives a '404 Not Found' error. The user can successfully list the engine at 'secret/' with `vault secrets list`. What is the most likely cause of the 404 error?
Medium178An administrator wants to audit token usage without exposing the actual token IDs to auditors. Which approach should they use?
Hard179A token with the above policy attempts to look up its own token by calling the accessor endpoint. What will happen?
Easy180A Vault administrator is configuring a new Vault server and wants to ensure that audit logs capture every request and response, including the ability to detect tampering. Which Vault architectural component is responsible for providing this capability?
Easy181Which TWO of the following are benefits of using dynamic secrets engines (e.g., database, AWS) over static secrets?
Medium182An operator has authenticated to Vault and wants to inspect the metadata of the currently active token, including its accessor, policies, and creation time, without exposing the token's secret value. Which CLI command returns this information?
Medium183An administrator configures AppRole with a RoleID and SecretID. They want to ensure that each SecretID can be used only once. Which configuration should they use?
Hard184An organization uses the KV v2 secrets engine mounted at 'kv/'. They need to permanently delete all versions of a secret at path 'kv/apps/prod/db' and also remove all associated metadata, including custom metadata and version history. Which command should they run?
Hard185An operator creates a batch token for a one-time database migration. The migration finishes, and the operator wants the token to be unusable immediately, even before its TTL expires, and wants to confirm the token no longer appears in the token list. Which Vault command accomplishes this?
Hard186Refer to the exhibit. A user attempts to renew the token after 20 hours. What will happen?
Hard187An operator runs `vault token create -policy=app -ttl=1h -explicit-max-ttl=2h` and then checks the token's properties with `vault token lookup`. The token is renewable. A developer asks whether the token can be kept alive indefinitely by renewing it every 30 minutes. What should the operator tell the developer?
Medium188An administrator is configuring Vault to allow employees to log in using their existing corporate credentials managed by an external identity provider that supports OIDC. The administrator wants to avoid creating local Vault users. Which authentication method should be used?
Medium189A developer needs to manually revoke a token but only knows its accessor. Which Vault API endpoint can be used to revoke the token using only the accessor?
Medium190A Vault administrator is troubleshooting a batch of revoked database credentials. An application reported that its lease stopped working even though the application had been renewing it every few minutes. Reviewing the mount configuration, the administrator sees default_lease_ttl set to 15m and max_lease_ttl set to 2h. The application log shows successful renewals until roughly the two-hour mark, after which the renew call returned an error and the credential failed. What is the most likely explanation?
Hard191A cloud operations team wants to use Vault to generate dynamic credentials for an AWS RDS MySQL database. They have configured the database secrets engine and created a role named 'app-role' that maps to a database creation statement. A developer needs to obtain a username and password to connect to the database. Which command should the developer run to retrieve the dynamic credentials?
Easy192A Vault user wants to check the capabilities of their token on a specific path. Which command should they use?
Easy193A financial services company runs a microservices application on Kubernetes. Each service needs to authenticate to Vault using Kubernetes auth and then read secrets from a shared KV v2 engine mounted at 'shared-kv'. The security team requires that Service-A can only read secrets under 'shared-kv/team-alpha/*' and Service-B can only read secrets under 'shared-kv/team-beta/*'. The Vault administrator has already configured the Kubernetes auth method and created roles for each service with bound service account names. However, both services are currently able to read all paths under 'shared-kv/'. The administrator wants to enforce the least privilege access. Which course of action should the administrator take?
Medium194A financial services company uses HashiCorp Vault's transit engine to encrypt customer credit card numbers. The application sends each credit card number individually to Vault for encryption, and the response time is acceptable. However, during peak hours, the company needs to encrypt large batches of 10,000 credit card numbers. Users report that encrypting the entire batch takes several minutes, causing timeouts. The Vault cluster is healthy and not under high load. The security team wants to reduce the encryption time without changing the encryption algorithm or key strength. What should they do?
Medium195A developer authenticates with the userpass auth method and receives a token. The developer needs to perform a sensitive operation but the token lacks the required policy. Before asking an administrator, the developer wants to determine whether their current token is permitted to update the secret at secret/data/payments. Which command should the developer run?
Medium196A user with this policy wants to delete secrets under the 'team/' path. Which additional capability must be added?
Hard197A small company uses Vault with LDAP authentication for their employees. They configured the LDAP auth method pointing to their on-premises Active Directory. Several users report that they can log in to the Vault UI, but they cannot see any secrets in the paths they expect. The administrator verified that the users are in the correct AD groups. The Vault policies are defined and assigned to groups via the LDAP auth method's group mapping. However, the users still have no permissions. What is the most likely root cause and the correct fix?
Easy198A security team wants to ensure that tokens can be revoked immediately if a compromised token is detected, even if the token ID is unknown. Which token feature should they use?
Easy199A company has multiple AWS accounts and wants to allow EC2 instances to authenticate to Vault without storing any secrets on the instances. Which authentication method should they use?
Medium200An administrator creates a service token with a TTL of 1 hour and a max TTL of 24 hours. The token is renewed once after 55 minutes. What happens to the token after 24 hours from creation?
Easy201A security engineer needs to ensure that if a key is compromised, previous ciphertext can be re-encrypted with a new key version without exposing the plaintext. Which Vault operation should they use?
Hard202A Vault operator is troubleshooting a newly deployed Vault server that is initialized but not yet unsealed. The operator needs to understand which component is responsible for holding the unseal keys and root token during the initialization process. Which statement accurately describes the role of the barrier in Vault's architecture?
Medium203A developer wants to use Vault to encrypt sensitive data before storing it in a database. They need to perform encryption and decryption operations without ever exposing the encryption key. Which secrets engine should they use?
Easy204An organization wants to use Vault's dynamic database credentials to manage MySQL access. They have multiple application servers that need to connect to different databases. What is the best practice for configuring database roles to minimize the number of Vault mounts?
Easy205Drag and drop the steps to set up Vault's Kubernetes auth method into the correct order.
Medium206An administrator is troubleshooting a policy where a token unexpectedly has permission to read 'secret/data/finance/payroll' even though the attached policy only contains a statement for 'secret/data/hr/*'. The administrator confirms the policy is attached correctly and the path is not covered by any wildcard in it. What is the most likely explanation?
Medium207A team wants to store encrypted backups in object storage and needs the ability to rotate the wrapping key over time without re-uploading every backup object. They also want the plaintext data key to be used only in memory by the backup agent. Which combination of Vault transit operations best fits this design?
Hard208A security engineer configures the Transit secrets engine at transit/ to encrypt application data. The application must be able to decrypt data but must not be able to create new encryption keys or rotate existing ones. Which policy snippet correctly grants only the required capability for the application's token?
Medium209A policy must allow a user to revoke their own token. Which endpoint and capability are required?
Easy210An operator needs to create a token role named 'web-app' with a default TTL of 24 hours. Which API request is correct?
Medium211Match each Vault term to its definition.
Medium212A Vault operator discovers that a service account token was compromised, and that token had created several dynamic database credentials across multiple roles. The operator needs to invalidate every lease created by that token as quickly as possible rather than waiting for each lease to expire. Which action accomplishes this?
Medium213A company uses Vault to store application configuration secrets for multiple teams. The Vault cluster is running in production and has the KV secrets engine enabled at the path 'secret/' using version 2. A DevOps engineer, using a Vault token with full admin access, creates a new secret at 'secret/data/team-a/app-config' using the CLI command 'vault kv put secret/team-a/app-config key=value'. The secret is intended for the CI/CD pipeline, which uses a token with a policy that grants 'read' capability on 'secret/data/*'. The pipeline is configured to read the secret by calling the Vault API at the path 'v1/secret/team-a/app-config'. The pipeline reports a 404 Not Found error. The pipeline engineer verifies that the token is valid and has the correct policy attached. All other secrets in the same path can be read successfully by the pipeline. What is the most likely cause of the 404 error?
Hard214A Vault admin wants to revoke a specific lease for a dynamic database credential. The admin has the lease ID. Which command should the admin use?
Hard215A DevOps team is using Vault tokens with short TTLs for CI/CD jobs. They notice that some jobs fail intermittently with 'permission denied' errors even though the token policy grants the required capabilities. The token is created with a TTL of 10 minutes and renewed automatically by the client library. What is the most likely cause of the failures?
Medium216Which THREE of the following are true about using the Vault API with response wrapping? (Choose three.)
Hard217A security engineer creates a service token with a TTL of 1 hour and a max TTL of 4 hours. The token is used by an application that renews it every 30 minutes. After 3 hours, the engineer revokes the token using its accessor. What happens to the token's child tokens?
Hard218A security engineer needs to create a batch token that will be used by an external system for a one-time operation. The token must be self-contained and not stored in Vault's storage backend. Which token type should be used, and what is a key limitation of that token type?
Medium219A developer wants to store an API key for their application in Vault using the key-value secrets engine. They need to be able to retrieve the key and also roll back to a previous version if needed. Which secrets engine configuration should they use?
Easy220Drag and drop the steps to initialize and unseal a Vault server for the first time into the correct order.
Medium221Which THREE of the following best practices should be followed when using Vault's encryption as a service with the transit engine?
Medium222A company wants to use Vault to generate IAM users dynamically for each application, following the principle of least privilege. Which secrets engine configuration should they use?
Medium223A CI/CD pipeline runs in a Kubernetes cluster and needs to authenticate to Vault to fetch secrets. The pipeline should not have to manage any long-lived credentials. Which authentication method is most suitable?
Easy224A Vault administrator is configuring a new Vault server. The server will store secrets in a HashiCorp Consul cluster. The administrator writes a configuration file with the `storage` stanza pointing to Consul and starts Vault. After initialization and unsealing, the administrator notices that Vault is functioning but wants to ensure that the storage backend is highly available. Which statement about Vault's storage backend is accurate?
Easy225Match each Vault replication type to its behavior.
Medium226An admin wants to list all enabled authentication methods using the Vault API. Which curl command is correct?
Hard227A security team wants to ensure that database credentials generated by Vault are never renewed and have a fixed lifespan of 30 minutes. They configure the role with default_ttl=30m and max_ttl=30m, and set renewable=false. However, they find that some users are able to renew the leases anyway. What could be the reason?
Hard228A small development team wants engineers to log in to Vault with a username and password stored directly in Vault, without integrating any external directory or identity provider. Which authentication method should the administrator enable to satisfy this requirement?
Easy229Which TWO statements are true about batch tokens?
Easy230A security team wants to audit all tokens created by a specific authentication method. They need to list all tokens and retrieve details such as creation time, TTL, and policies. Which Vault command should they use?
Medium231A security engineer enables the Transit secrets engine at 'transit/' and creates an encryption key named 'payments' with `vault write -f transit/keys/payments`. The engineer then wants to rotate the key so that new data is encrypted with a new key version while existing ciphertext can still be decrypted. Which command accomplishes this without invalidating existing ciphertext?
Hard232An operator runs vault lease list and sees many expired leases. Why are expired leases still listed?
Medium233An application needs to obtain short-lived, time-limited credentials to access an external database using username/password authentication. Which secrets engine should be used?
Medium234An organization is creating Vault policies to manage access to secrets across multiple application teams. According to HashiCorp best practices, which two approaches should be taken when designing policies? (Choose two.)
Medium235An operator needs to create a periodic token with a period of 36 hours. Which command should they use?
Medium236A DevOps team wants to authenticate to Vault using short-lived tokens without storing a secret in their CI/CD pipeline. Which authentication method best meets this requirement?
Easy237A security architect is designing a Vault deployment where the root key must never exist in plaintext outside of memory and must be split among five key holders. After initialization, the architect wants to ensure that no single administrator can unseal the vault alone. Which Vault architectural feature directly enforces this requirement?
Hard238A developer wants to log in to Vault from a terminal by supplying a username and password that Vault stores and manages internally, without relying on any external identity system. Which auth method should be enabled?
Easy239A platform team runs Vault with a transit secrets engine mount at transit/. An application requests a new data encryption key with a 30-minute TTL, and the returned lease_id is recorded by the app. Twenty minutes later, the app calls the renew endpoint for that lease. The mount was configured with max_lease_ttl of 1h. What is the maximum TTL the lease can be extended to by this renewal?
Medium240Refer to the exhibit. A user with this policy tries to write a new secret to "secret/data/production/db". What will happen?
Easy241An administrator wants to allow human users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?
Easy242Which THREE are best practices when selecting authentication methods for different use cases?
Hard243A company uses Vault's Kubernetes authentication method to provide secrets to pods. Pods in the 'production' namespace need to read secrets from the path 'secret/data/app/prod'. The administrator has created a Vault role that maps the service account to a policy with capabilities ['read', 'list'] on path 'secret/data/app/*'. However, pods report 'permission denied' when trying to read the secrets. The administrator verifies that the service account has the correct Vault role attached and that the Vault token is being used correctly. What is the most likely cause?
Hard244An organization uses Vault's AWS secrets engine to generate temporary IAM credentials. The Vault administrator has set the default lease TTL on the AWS mount to 15 minutes. A developer creates a role with role TTL of 30 minutes and explicit max TTL of 1 hour. Which TWO statements are true regarding the lease behavior for credentials generated under this role?
Hard245A developer needs to authenticate to Vault from a CI/CD pipeline running on an on-premises server. The pipeline cannot use cloud provider identities or Kubernetes. The security team wants to avoid embedding long-lived Vault tokens in the pipeline scripts. Which authentication method is most appropriate?
Easy246During an audit, it is discovered that a single AppRole role is used by hundreds of applications, and it is impossible to revoke access for a single compromised application without affecting others. What should be done to improve the security posture?
Hard247A developer needs to encrypt a short configuration string with the Vault transit secrets engine. The transit engine is mounted at `transit/` and a key named `app-config` has already been created. Which single CLI command correctly sends the plaintext to Vault for encryption?
Easy248A platform team wants to provide applications with short-lived AWS credentials that are automatically revoked when their lease expires, without managing long-term IAM users. They also need to allow the applications to assume a role for cross-account access. Which secrets engine should the team enable and configure?
Easy249A platform team runs Vault 1.15 with an integrated storage backend. They have enabled the KV v2 secrets engine at the path 'apps/'. A developer deletes the secret at 'apps/data/webapp/db-creds' using `vault kv delete apps/webapp/db-creds`, then immediately reads it back with `vault kv get apps/webapp/db-creds`. What does the developer observe?
Medium250A developer created a token and wants to ensure that the token can only be used to read secrets from the 'secret/data/production' path. Which policy attachment approach should be used?
Easy251A Vault administrator wants to minimize the impact of a single node failure in a three-node Raft cluster. Which TWO actions will help? (Choose two.)
Hard252Which TWO of the following are valid methods to enable a secrets engine at a non-default path in Vault?
Hard253A developer needs to generate a new certificate for an internal web service using the PKI secrets engine. A role named 'webserver' has been created. What is the correct command to issue the certificate?
Medium254A Vault administrator wants to allow a CI/CD pipeline to create short-lived tokens for deployment jobs. The pipeline itself authenticates with a periodic token. Which token type should the pipeline use to create tokens for jobs, considering the jobs need to be independent and not affected by the pipeline token's lifecycle?
Medium255A developer wants to encrypt a password before storing it in a database. The encryption must be deterministic so that the same plaintext always produces the same ciphertext. Which encryption mode should be used in the transit secrets engine?
Medium256Which of the following best describes a Vault lease?
Easy257A Vault administrator is writing a policy that uses a templated path to allow each user to access their own secrets. The policy is: path "secret/data/users/{{identity.entity.id}}/*" { capabilities = ["read", "list"] } When a user with entity ID "1234" attempts to read 'secret/data/users/1234/profile', they receive a permission denied error. The secret exists, and the user's token has this policy attached. What is the most likely reason for the failure?
Hard258A Vault administrator manages a high-availability cluster with Integrated Storage (Raft) and three nodes. The cluster is healthy with one active node and two standby nodes. The administrator needs to perform a planned upgrade of the active node. Before stepping down, the administrator wants to ensure that the standby nodes are ready to take over and that no data loss occurs. Which action should the administrator take to safely transfer leadership?
Hard259An operator manages a Vault cluster where several auth methods are enabled at different paths. A developer reports that logging in with the Kubernetes auth method succeeds, but the resulting token has no permissions. The operator confirms the role exists and the service account JWT is valid. Which configuration element is most likely missing?
Medium260A CI pipeline authenticates to Vault using the AppRole auth method and needs to obtain a token non-interactively. The pipeline has a role_id and a secret_id but cannot use an interactive login prompt. Which TWO methods can the pipeline use to authenticate and receive a token? (Choose two.)
Medium261A security architect is designing a service that uses the Vault transit engine to encrypt records. The architect wants to limit the blast radius if an application token is stolen. The application only ever writes new encrypted records and never needs to read them back. Which transit policy capability set should be granted to the application token?
Medium262A company uses Vault to manage secrets for multiple applications. A new security policy requires that all human users authenticate using LDAP and that all machine-to-machine authentication uses AppRole. An administrator has configured an LDAP auth method at 'ldap/' and an AppRole at 'approle/'. The administrator creates a role 'web-app' with a secret ID TTL of 30 days and a token TTL of 1 hour. After deploying the web application, the application successfully logs in using the AppRole role ID and secret ID, retrieves a token, and reads secrets. However, after 1 hour, the application begins receiving 'permission denied' errors when trying to read secrets. The application logs show that it is using the same token obtained during initial login. Which action should the administrator take to resolve this issue?
Easy263An administrator wants to mount the AWS secrets engine at 'aws' path using the API. Which request is correct?
Medium264Drag and drop the steps to configure Vault's database secrets engine with PostgreSQL into the correct order.
Medium265A company uses OIDC auth for human users. After the OIDC provider rotates its signing keys, some users report that they cannot authenticate. The Vault logs show that the OIDC response validation fails. What is the most likely cause?
Medium266A developer wants to ensure that their application automatically renews its secret leases before expiration. Which approach is recommended?
Medium267A platform team stores application configuration and credentials in a KV v2 secrets engine mounted at 'kv/'. A developer deleted version 3 of the secret 'kv/app/db' by running 'vault kv delete kv/app/db'. Two days later, the security team asks the developer to recover that version because it contained a valid certificate. The developer runs 'vault kv get -version=3 kv/app/db' and receives an error that the version has been deleted. What must the developer do to recover version 3?
Medium268A DevOps team is deploying Vault in a Kubernetes cluster. They want to ensure that when a pod starts, it can obtain a short-lived Vault token without human intervention. Which Vault architecture component should they use?
Medium269A Vault administrator wants to allow users to authenticate using their corporate Active Directory credentials. Which authentication method should they enable?
Medium270A cloud operations team needs Vault to issue short-lived credentials for an external MySQL database. They want Vault to create and revoke users dynamically based on a role. Which secrets engine should they enable and configure?
Easy271A company is deploying Vault in a Kubernetes environment. Which three components are essential for a production-ready Vault on Kubernetes? (Choose three.)
Medium272A company uses Vault transit to encrypt secrets. They want to periodically rotate the encryption key to comply with compliance requirements. Which TWO actions should be taken? (Choose two.)
Medium273An administrator is configuring a new PKI secrets engine at pki/ to issue TLS certificates for internal services. The security team requires that the intermediate CA certificate and its private key are generated inside Vault, and that the root CA remains offline. Which command should the administrator run to create the intermediate CA and generate a CSR for signing by the offline root?
Medium274A Vault administrator is reviewing token behaviors and needs to understand which actions are possible with a token's accessor. Which two statements about token accessors are true? (Choose two.)
Medium275Match each Vault auth method to its authentication mechanism.
Medium276A token with a policy granting 'write' on 'secret/team-alpha/*' is unable to write to 'secret/team-alpha/db-creds' in a KV v2 engine. What is the most likely cause?
Medium277An administrator is reviewing Vault token policies and wants to ensure that tokens created by a specific application cannot be renewed and have a fixed lifetime. Which two token configurations should be applied?
Medium278A company deploys Vault in a production environment with three nodes using Integrated Storage (Raft). They have configured Performance Replication to a secondary datacenter. The primary datacenter experiences a complete outage. After restoring the primary, they promote the secondary to primary. However, they notice that some secrets written to the primary just before the outage are missing in the secondary. The replication status shows no errors. What is the most likely cause and correct action?
Hard279A team is adopting Vault and wants to organize secrets by application and environment (e.g., production, staging). What is the best practice for secrets engine path naming?
Medium280A Vault administrator wants to configure a role for dynamic secrets with a default TTL of 1 hour and a max TTL of 4 hours. They also want to allow renewal but only up to the max TTL. Which configuration achieves this?
Medium281An administrator wants to create a policy that grants the ability to list all authentication methods enabled on the Vault server. Which path and capability are required?
Medium282A team maintains a shared policy that many tokens reference. An administrator needs to add a new path stanza to the policy while preserving every existing rule, without risking a typo that silently removes access. Which approach is correct?
Medium283An administrator wants to allow users to authenticate to Vault using their existing corporate GitHub accounts. Which authentication method should be enabled?
Easy284A platform team must let a batch job encrypt large files, up to several gigabytes each, using Vault transit. Sending entire files to Vault would exhaust request size limits and add latency. Which approach correctly uses the transit engine while keeping key material inside Vault?
Hard285What command is used to view the remaining time on a lease?
Easy286A company wants to securely store database credentials for a dynamic application that spins up new instances frequently. They need to ensure each instance gets a unique, time-limited username/password pair with minimal operational overhead. Which approach should they use?
Medium287An organization uses the Transit secrets engine to encrypt sensitive files. They want to rotate the encryption key regularly without re-encrypting all existing files. Which feature allows this?
Medium288An operator configures a PKI role with allow_any_name=true and max_ttl=72h. A user requests a certificate with common_name='admin.example.com' and ttl=48h. What is the resulting TTL?
Medium289What is the purpose of the `storage` stanza in a Vault server configuration file?
Easy290A Vault administrator is explaining the role of the storage backend in Vault's architecture. A new team member asks where Vault stores its encrypted data and what the storage backend is responsible for. Which statement accurately describes the storage backend's role?
Easy291A user forgets to renew their token before it expires. What happens to the token and its associated leases?
Easy292An operations team manages Vault leases for dynamic database credentials. They need to extend the life of an active lease without issuing a new credential, and they also want to confirm the lease's remaining time before doing so. Which two commands or operations should they use? (Choose two.)
Medium293A company is running Vault in production with a single active node and two standby nodes using Integrated Storage. The operations team notices that after a network partition, one of the standby nodes becomes unavailable for a few minutes. Upon recovery, the node rejoins the cluster. However, the active node's performance degrades temporarily. What is the most likely cause?
Medium294Which THREE steps are required to configure the database secrets engine for generating dynamic credentials?
Hard295Which two of the following are valid lease operations? (Choose two.)
Easy296An administrator wants to ensure that a token created by a user cannot be used after 24 hours, even if the user tries to renew it. What should the administrator do?
Hard297Refer to the exhibit. A Vault administrator configures a three-node cluster with the above configuration on all nodes (with appropriate node_id). After starting all nodes, the administrator unseals node2 and node3. Node1 remains sealed. What will be the cluster state?
Medium298An organization needs to store secrets with versioning support, allowing rollback to previous secret values. Which KV secrets engine version should be enabled?
Hard299Which TWO are core components of Vault's architecture?
Easy300Which TWO of the following are valid methods to authenticate to Vault using the CLI without using a token? (Choose two.)
Easy301A Vault cluster uses a Consul storage backend. During a maintenance window, the Consul cluster is taken offline for upgrades. Vault nodes remain running but become unresponsive. After Consul is restored, Vault nodes resume normal operation without manual intervention. Which Vault architectural property explains this behavior?
Medium302A security architect is designing a system where one microservice writes encrypted records and a separate reporting microservice reads them. The architect wants the writer to be unable to decrypt anything, while the reader can decrypt but cannot create new ciphertext. Which Vault policy design achieves this with the transit engine?
Hard303A security engineer is comparing the AppRole and Kubernetes auth methods for a containerized application. The application runs in a Kubernetes cluster and needs to authenticate to Vault. The engineer wants to minimize the risk of secret leakage and avoid manual secret rotation. Which statement best describes the advantage of Kubernetes auth over AppRole in this scenario?
Hard304A cloud operations team needs to provide temporary, dynamically generated credentials for an AWS IAM user to a CI/CD pipeline. The credentials must be automatically revoked when the lease expires. They have configured the AWS secrets engine at 'aws/' with root credentials. Which configuration step is required to allow the pipeline to assume a specific IAM role and receive credentials?
Medium305Match each Vault policy capability to its permission.
Medium306A payment processing team needs an application to encrypt transaction payloads without ever handling the raw encryption key material. The application will call Vault over mTLS, and the security team insists that the plaintext never leave the application process. Which Vault capability best satisfies this requirement?
Medium307Which THREE of the following are true statements about the AppRole authentication method? (Choose three.)
Hard308Which THREE are benefits of using Vault response wrapping?
Medium309An organization wants to encrypt sensitive fields in their database using Vault. They have multiple applications that need to encrypt different types of data. What approach should they take?
Medium310An administrator needs to securely provide a one-time use token to a remote service using Vault response wrapping. Which CLI flag or command should they use?
Hard311An organization wants to encrypt data in transit and at rest using a centralized key management system. Which secrets engine is designed for encryption/decryption operations without storing data?
Easy312A security analyst discovers that a token used by a legacy application is still active long after the application was decommissioned. Which Vault feature should have been used to automatically expire tokens when the application is no longer running?
Medium313An administrator is evaluating Kubernetes auth for workloads running in a cluster. A developer asks whether a pod can authenticate by presenting a service account token directly to Vault without Vault contacting the Kubernetes API. Which statement best describes how the Kubernetes auth method actually validates a login?
Hard314Refer to the exhibit. A developer tries to renew a token and receives this error. The token was created using 'vault token create -type=batch'. What is the most likely cause of this error?
Medium315An organization needs to automatically issue X.509 certificates for internal services. Which secrets engine should they use?
Easy316Which authentication method in Vault uses a shared secret (Role ID) and a dynamic secret (Secret ID) to authenticate machines or applications?
Easy317After a security incident, the Vault administrator needs to change the encryption key used to encrypt data at rest. They have already rekeyed the unseal keys. What additional step is required to ensure new secrets are encrypted with a new key?
Hard318A security audit requires tracking token usage without exposing the token value itself. Which token attribute should be logged?
Medium319A security engineer is building an application that must encrypt records before writing them to an external SaaS ticketing system. The application must never receive or store the encryption key material, and the same plaintext must always produce the same ciphertext so records can be looked up by their encrypted value. Which transit engine configuration should be used?
Medium320A platform team enables the transit engine and creates a key named orders. After several months the team rotates the key. A batch job that had stored ciphertext produced before the rotation now needs to read the original data. What must happen for the batch job to recover the plaintext?
Medium321Which THREE of the following are correct about using the Vault API to read a secret from KV v2 engine?
Hard322A DevOps engineer is configuring Vault to encrypt data in transit for a microservice. They create a key in the transit engine and want to encrypt a base64-encoded plaintext. Which API path and operation should they use?
Medium323Drag and drop the steps to enable AppRole authentication in Vault into the correct order.
Medium324In a Vault HA cluster, which node is responsible for handling all write requests?
Easy325A Vault operator runs 'vault secrets list' and sees 'cubbyhole/' mounted. What is the purpose of this engine?
Easy326A DevOps engineer needs to create a token with a specific policy attached using the Vault API. Which API endpoint and request should they use?
Hard327Drag and drop the steps to configure Vault's audit logging to a file into the correct order.
Medium328Which TWO of the following actions can reduce the number of active leases in Vault? (Select two.)
Easy329A startup wants to use Vault to manage MySQL database credentials for their development environment. They have a single MySQL database and require that each application gets unique, short-lived credentials that are automatically rotated. The operations team enabled the database secrets engine, configured the MySQL connection, and created a role with a TTL of 1 hour. However, when an application requests credentials using the role, Vault returns an error: 'No more available leases on this role'. The team checks the role's configuration and sees that the 'max_ttl' is set to 1 hour and 'default_ttl' is also 1 hour. What is the most likely cause of this error?
Easy330An administrator creates a token with the following parameters: `vault token create -ttl=1h -explicit-max-ttl=2h`. The token is then renewed once for 1 hour. What is the maximum remaining time the token can be renewed for after this first renewal?
Easy331A Vault cluster is sealed. An operator attempts to renew a lease but gets an error. What is the most likely error?
Hard332Which THREE are appropriate use cases for Vault's Transit secrets engine?
Medium333A user receives 'permission denied' when running 'vault write secret/data/myapp value=123'. The user's token has a policy that includes 'path "secret/data/*" { capabilities = ["read", "list"] }'. What is the most likely cause?
Hard334A company uses Vault to issue tokens for short-lived tasks. They have configured a token role with 'period' set to 30 minutes and 'explicit_max_ttl' set to 24 hours. Tokens are created using the role and are expected to be renewed every 30 minutes by the tasks. However, after a few renewals, the Vault audit logs show that a token was renewed but then immediately expired. The task that was using the token failed. What is the most likely reason for this behavior?
Medium335Refer to the exhibit. An application uses this policy to access Vault. The application is able to read database credentials from `database/creds/my-role`. However, attempts to list all roles at `database/roles/` fail. What is the most likely cause?
Hard336A company requires that Vault data be continuously replicated from a primary data center to a secondary data center for disaster recovery. The secondary data center must be able to become writable in the event of a primary failure. Which Vault feature should they use?
Hard337An application uses a periodic token with period=24h. The application renews every 12h. After 48h, the token is still valid. After 72h, the token is still valid. What is the maximum lifetime of this periodic token?
Hard338A security engineer needs to authenticate a CI pipeline to Vault using the AppRole auth method from the CLI without a pre-existing token. The engineer has the role_id and a wrapped secret_id. Which TWO commands are required to complete the login and obtain a usable token? (Choose two.)
Medium339A security engineer is comparing two machine-oriented auth methods for workloads running outside Kubernetes. The workloads cannot use cloud instance identity and must not store a long-lived credential on disk. The engineer wants a method where the workload proves possession of a one-time-use credential that can be issued with a very short TTL and limited use count. Which auth method best fits?
Hard340A developer has a policy that grants 'create' capability on path 'secret/data/team/*'. They successfully create a new secret using 'vault kv put secret/data/team/db', but when they try to update the same secret with new data, they get a permission denied error. What is the most likely cause?
Medium341After rotating the 'payment-key', Vault successfully decrypts data encrypted with the old key (v1). What is the most likely reason the decryption succeeded?
Hard342A Vault policy includes the following statement: path "secret/data/+/app" { capabilities = ["read"] }. Which paths would match this policy? (Assume KV v2)
Hard343An organization uses the AWS secrets engine to generate IAM users for each application. They want to ensure that if a Vault server is compromised, the attacker cannot use the AWS secrets engine configuration to gain access to the AWS account. Which additional security measure should be implemented?
Hard344A Vault cluster has several policies. One policy, "app-policy", contains: path "secret/data/app/*" { capabilities = ["create", "update"] }. Another policy, "admin-policy", includes: path "secret/data/app/db" { capabilities = ["deny"] }. A token is attached with both policies. Can the token write to "secret/data/app/db"?
Hard345A financial services company uses Vault's PKI secrets engine to issue short-lived TLS certificates to internal services. An administrator configured the PKI role with default_ttl=24h and max_ttl=72h. A service requests a certificate with an explicit TTL of 120h. What will Vault do in this situation?
Hard346A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?
Medium347Which TWO of the following are valid use cases for the Transit secrets engine? (Select exactly 2.)
Medium348A Vault cluster uses Consul for HA. After a brief network partition, a standby node loses contact with the active node. What does the standby node do after a timeout?
Easy349A Vault cluster uses performance replication. A performance standby node is not responding to read requests. What is the most likely cause?
Medium350Refer to the exhibit. What seal mechanism is configured for this Vault instance?
Medium351Refer to the exhibit. What is the purpose of the -field=ciphertext flag in this command?
Medium352A security engineer wants to ensure that all requests to Vault are logged for compliance. Which component must be configured?
Easy353Which THREE are required for Vault to encrypt data at rest? (Choose three.)
Medium354An administrator wants to write a secret 'myapp' with value 'password=pass123' to the KV v2 secret engine mounted at 'secret/'. Which command should they use?
Easy355A team has set up automatic key rotation on a transit key. After rotation, encrypted data that was encrypted with the previous key version can no longer be decrypted. What is the most likely cause?
Hard356Which TWO of the following are features of the AWS secrets engine compared to the Azure secrets engine?
Easy357An organization uses Kubernetes pods to access Vault. They want to avoid hardcoding any secrets in the pod definition. Which authentication method should they use?
Medium358A DevOps team is setting up a Vault cluster for the first time. They plan to use AWS KMS for auto-unseal and Consul as the storage backend. As part of the architecture, which TWO components are essential for the Vault server to start and serve requests?
Easy359Refer to the exhibit. A user wants to write a secret 'db_password' with value 's3cret' to this secrets engine. Which CLI command should be used?
Easy360A security team is evaluating the Vault transit secrets engine as an encryption-as-a-service platform for several applications. They want to understand which capabilities the transit engine actually provides. (Choose two.)
Medium361An organization wants to encrypt data at rest in a cloud storage bucket. They plan to use Vault's transit engine to generate a data key and then encrypt the data locally. Which transit endpoint should they use to get a data key?
Easy362A Vault cluster has a token with the following policy: path "secret/data/dev/*" { capabilities = ["read", "list"] }. The token is used to read a secret at "secret/data/dev/password". The read succeeds. Later, the token tries to read "secret/data/prod/password". What happens?
Hard363A security engineer is enabling the Transit secrets engine at the path 'transit/'. They need to encrypt data without ever exposing the plaintext key material to the application, and they want the ciphertext to be safely stored in an external database. They also require the ability to rotate the encryption key periodically without re-encrypting existing data. Which command correctly configures a new encryption key named 'orders' for this purpose?
Medium364Which THREE are valid operations in the Vault transit secrets engine? (Choose three.)
Medium365A security administrator wants to create a policy that allows a service to renew its own token and list its own token capabilities, but not create new tokens. Which policy statements should be included?
Medium366Drag and drop the steps to perform a Vault disaster recovery using the replication feature into the correct order.
MediumOther domains
All VA-003 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the VA-003 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 366 troubleshooting questions in the VA-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.